CompTIA SecurityX Practice Questions: Risk Management

5 free, exam-style CompTIA SecurityX (CAS-005) practice questions covering Risk Management. Each question shows the correct answer and a clear explanation. Ready for the real thing? Take the full timed quiz below.

🚀 Take the full CompTIA SecurityX quiz 📘 CompTIA SecurityX study guide

Q1. Which framework is MOST commonly used for enterprise risk management?

Explanation: NIST Cybersecurity Framework (CSF) is widely adopted for risk management. Learn more.

Q2. What is the PRIMARY purpose of a Business Impact Analysis (BIA)?

Explanation: A BIA identifies essential functions for disaster recovery planning. Learn more.

Q3. What does risk appetite define for an organization?

Explanation: Risk appetite is a leadership-level statement of acceptable risk in pursuit of business objectives. Learn more.

Q4. What is the main value of a control gap assessment?

Explanation: A gap assessment compares current control maturity against standards, requirements, or desired states. Learn more.

Q5. Which metric measures how often a loss event is expected to occur in a year?

Explanation: Annualized rate of occurrence estimates how frequently a risk event may happen per year. Learn more.

More CompTIA SecurityX practice topics